Towards Physically Realizable Adversarial Attenuation Patch against SAR Object Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Yiming, Qin, Weibo, Wang, Feng
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915908158488576
author Zhang, Yiming
Qin, Weibo
Wang, Feng
author_facet Zhang, Yiming
Qin, Weibo
Wang, Feng
contents Deep neural networks have demonstrated excellent performance in SAR target detection tasks but remain susceptible to adversarial attacks. Existing SAR-specific attack methods can effectively deceive detectors; however, they often introduce noticeable perturbations and are largely confined to digital domain, neglecting physical implementation constrains for attacking SAR systems. In this paper, a novel Adversarial Attenuation Patch (AAP) method is proposed that employs energy-constrained optimization strategy coupled with an attenuation-based deployment framework to achieve a seamless balance between attack effectiveness and stealthiness. More importantly, AAP exhibits strong potential for physical realization by aligning with signal-level electronic jamming mechanisms. Experimental results show that AAP effectively degrades detection performance while preserving high imperceptibility, and shows favorable transferability across different models. This study provides a physical grounded perspective for adversarial attacks on SAR target detection systems and facilitates the design of more covert and practically deployable attack strategies. The source code is made available at https://github.com/boremycin/SAAP.
format Preprint
id arxiv_https___arxiv_org_abs_2604_00887
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Towards Physically Realizable Adversarial Attenuation Patch against SAR Object Detection
Zhang, Yiming
Qin, Weibo
Wang, Feng
Computer Vision and Pattern Recognition
Cryptography and Security
Deep neural networks have demonstrated excellent performance in SAR target detection tasks but remain susceptible to adversarial attacks. Existing SAR-specific attack methods can effectively deceive detectors; however, they often introduce noticeable perturbations and are largely confined to digital domain, neglecting physical implementation constrains for attacking SAR systems. In this paper, a novel Adversarial Attenuation Patch (AAP) method is proposed that employs energy-constrained optimization strategy coupled with an attenuation-based deployment framework to achieve a seamless balance between attack effectiveness and stealthiness. More importantly, AAP exhibits strong potential for physical realization by aligning with signal-level electronic jamming mechanisms. Experimental results show that AAP effectively degrades detection performance while preserving high imperceptibility, and shows favorable transferability across different models. This study provides a physical grounded perspective for adversarial attacks on SAR target detection systems and facilitates the design of more covert and practically deployable attack strategies. The source code is made available at https://github.com/boremycin/SAAP.
title Towards Physically Realizable Adversarial Attenuation Patch against SAR Object Detection
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2604.00887